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TRANSACTION SIGNATURE 
BACKGROUND OF THE INVENTION 

This invention relates to information security for gaming macMne networks. 
5 More particularly, the present invention relates to protecting gaming machine transaction 
information stored in a database from unauthorized alteration. 

Gaming machines are becoming increasingly sophisticated. Many slot machines 
now employ CRT video display screens in place of more traditional mechanically-driven 
reel displays. Further, poker and other games of chance are nov^ commonly provided on 
10 electronic/video machines. 

To control and monitor gaming machine activity, many establishments emplby 
networks electronically linlcing iiumerous gaming machines. Frequently casinos connect 
tlieir gaining machines to a local area network. Sortie casinos have even connected 
multiple local area networks t6 wide area networks spanning multiple casinos. Such 
1 5 wide area networks allow groups of slot machines at various casinos to be connected to . 
one another for various purposes including use in "progressive" games. Progressive 
games allow jackpots from multiple machines in multiple locations to grow as one large 
jackpot. 

Transaction currency on gaming machines is also becoming more sophisticated. 

20 Where once only coin handling mechanisms were present on gaming machines, credit 
devices such as cash-out vouchers now find wide use. These credit devices 
electronically store user transactions and, when used in conjunction with electronic 
processing systems, they monitor user activity. Some casinos now issue magnetic player 
identification cards that players use to obtain awards for frequent playing. A player 

25 holding such card inserts it in a Card reader provided on a gaming machine before he or 
she begins play. Accoimting software on the local area network then detects the card 
insertion, notes the player identity and follows the machine activity. Other casinos now 
issue bar-coded tickets. When a player terminates interaction on a gaming machine, the 
gaming machine prints out a ticket, which includes the player's final status such as the 

30 time and a cash-out value. The player then retrieves the ticket and may redeem it for 
credit at another game or cash it out at a change booth or a pay machine. 

1 
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As mentioned, gaming transactions are now electronically stored, typically by the 
gaming machine network. Thus, each time a user completes a transaction on a gaming 
machine, the network stores the transaction information such as the time, the machine 
number and credit value of the device at transaction completion. When the user attempts 
to play another ganie .with the credit device, the network must redeem the value of the 
device, e.g., for game credit^ Similarly, when thfe user attempts redeem the device for a 
cash-out, the network must provide ihe cash value of the device. Upon redemption of 
the device at a gaming machine or at cash-out, the redemption vajue of the device is 
detenqined according to the user's last stored transaction in the network. 

Transaction iiiformation for the network is typically stored in a common location 
or database for consistent access by the gaming machines and casino personnel. Some 
casinos use conventional database managemeiit tools to store the transaction information. 
These database management tools generally permit open access for individuals on the 
network, e.g., casino.personnel. Unfortunately, this open access to the database also 
potentially allows authorized, and even in some cases unauthorized, individuals to 
tamper with the transaction informa.tion. In one example, an unscrupulous person could 
alter, the transaction amount in a database record from $10 to $100. 

From the foregoing, it should be apparent there exists a need for security 
measwes that prevent tampering of transaction information stored in a database of a 
gaming rietwork. 

SUMMARY OF THE INVENTldN 

The present invention provides systems and methods for protecting transaction 
information stored in a database of a gaming network. To accomplish this, a transaction 
signature is generated each time the user completes a transaction on a gaming machine. ^ 
The transaction signature is generated using transaction information from a particular 
transaction. The transaction signature and transactipn information are stored together in 
a network database. Upon subsequent access to the transaction information in tlie 
database, the transaction signature for the transaction information iis recalculated based 
on the transaction information at that time. The new transaction signature is then 
compared to the transaction signature previously stored. Any diJEferences between the 

2 



wo 02/22223 



PCT/llSOl/29112 



two transaction signatures may be used to signal unauthorized alteration in the database 
transaction information. 

Generating the transaction signature from the transaction information may be 
perfon-ned by various methods. Typically, this occurs each time the user completes a 
5 transaction with a gaming machine. In some embodiments, certain transaction attributes- 
or elements ofthoseath-ibutes are encrypted to generate the transaction si^ature. The ^ 
encryption may change over time in order to increase security of the- transaction 
infonnation in the database. 

In other embodiments, a portable credit device such as. a ticket or card is carried . ^ 
10 by the player and used during interaction with the gaming machines. Each time the user 
finishes interaction with a particular gamirig machine, the credit device is provided to the 
player wdth some of the updated transaction information. The credit device may have a 
magnetic strip or a semiconductor memory, for example, to store this information. For a 
ticket, the transaction infomiation maybe divided into elements such as a ticket 
15 validation number, a ticket amount, a ticket print time and date, a machine identifier, a 
cluster controller address and a ticket status. One or more of these transaction 
infonnation elements may be used to generate the transaction signature. The transaction 
i n Foi-mation and transaction signature are stored together in the database. 

At a subsequent time, when the transaction information is to be updated or called 
20 from the database, ttie transaction information and transaction signature are verified. 

This may occur, for example, when the player presents the credit device for redemption 
at another machine or at cash-out station. At that time, the transaction signature is 
recalculated based on the current transaction infonnation fi'om the device. This 
recalculated transaction signature is compared with the stored transaction signature in the 
25 database. If the two transaction signatures are consistent, the transaction infonnation 
may be updated or accessed. At this point, the credit can be redeemed. If the two 
transaction signatures are inconsistent, the transaction infonnation update or request may 
^' be stopped and further investigation may ensue. In addition to verifying the transaction 
signature, the transaction information may also be compared between the transaction 
30 information in the database and transaction information cvurently available fi-om the 
device. 
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These and other features and advantages of the invention will be described in 
more detail below with reference to the associated figures. 

BRIEF DEiSCRIPTIQN OF THE DRAWINGS 

FIG. 1 is a schematic diagram of a gaming machine network allowing electronic 
transfer of transaction information between a cential database and casino gaming 
machines iii accordance with the present invention. 

FIG. 2A illustrates an exemplary bar-coded ticket in accordance with one 
embodiment of the present invention. 

FIG. 2B illustrates an exemplary portion of code containing the transaction 
information and a transaction signature in accordance with a specific embo(^ment of the 
present invention. 

FIG. 3 illustrates a process flow to generate a transaction sigriahire iii accordance 
with one embodiment of the present invention. 

FIG. 4 illustrates a process- flow, to verify a transaction signature in accordance 
with one embodiment of the present invention. 

FIG. 5 illustrates an exemplary database for storing transaction information with 
transaction signature's in accordance with a specific embodiment of the present 
invention.. 



DESCRIPTrON OF THE PREFERRED EMBODIMENTS 

The present invention will now be described in detail with reference to a few 
preferred embodiments thereof as illustrated in the accompanying drawings. In the 
following description, numerous specific details are set forth in order to provide a 
thorough understanding of the present invention. It will be apparent, however, to one ' 
skilled in the art, that the present invention may be practiced without some or all of these 



WO.02/22223 PCT/US«1/29112 

specific details. . In other instances, well known process steps and/or structures have not 
been described in detail in order to not unnecessarily obscure the present invention. 

According to the present invention, transaction infonnation stored in a database 
or other data repository is secured by recording a transaction signature each time the 
5 •■• player completes a transaction with a gaming machine. The transaction signatiure is 

computed using certain elements of the gaming transaction information. The transaction 
information and transaction signature are stored together and verified each time tlie .. • 
.transaction information is accessed. Any inconsistency in the transaction infonnation or 
transaction signature between the current values and those previously stored may be used 
10 " to identify a transaction information discrepancy. This ensures that a person, such as ' 
someone gaining unauthorized access to the transaction data or even a privileged user,- 
cannot alter the stored transaction information. Thus, it becomes much more difQcult to 
cheat a casino by increasing the amoimt of credit associated with a transaction. 

FIG. 1 is a schematic diagram of a gaming machine network 100 that may be 
15 used witli the present invention. The network 100 includes a number of gaming 

machines 102. The gaming machines 102 permit a player to enter coins, bills, tickets or 
any other form of credit to begin a transaction between the player and a gaming machine. 
Upon completion of a transaction with a gaming machine 102, the player is issued a 
portable credit device, which will be described below. The gaming machine itself may 
20 issue the credit device. The network 1 00 electronically transfers transaction information 
between a central database lOi.and the gaming machines 102. For this purpose, the 
network 100 includes lines or cables 104, which may take various forms including 
coaxial wires, wireless connections or fiber optic cable. 

In some embodiments, numerous macliines 102 comiect to a single cluster 
25 controller or a Clerk Validation Terminal (CVT) 106. In one embodiment, a single CVT 
106 may accommodate up to 64 machines; The CVT 106 may store transaction 
• iriformation associated with the gaming machines 102. More specifically, the CVT 106 
*' may store credit device information corresponding to the. outstanding devices that are ■ 
waiting for redemption. Any of the machines connected to the CVT 106 will accept 
30 credit devices firom other gaming machines connected to the same CVT 106. The CVT 
106 may also contain additional memory for retaining redundant credit device 
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information. This may be used as a secondary storage medium for credit device 
information recovery in. the event of power failure or memory loss to the main memory 
in the network 100. In addition, players may redeem credit devices for cash at the CVT 
106 at anytime. 

' 5 " As there may be many groups of gaming maehines 102 in a large casino or other 

establishment, multiple CVTs 106 may be implemented. The CVTs 106 are connected 
to a local area network (LAN) 107 which includes a number of computers or 
..woilcstations as well as terminals, disk drives with fixed and/or removable media, 
. printers and other peripherals- connected on a token ring network; The computers on the 
1 0 LAN 1 07 may provide the casino with various functions such as processing j ackpots and 
fills, exporting of .transaction information to the central accounting system, and ■ 
generating accounting reports and security reports, etc: Other components connected to 
LAN 107 may include multiplexers, modems, and phone lines to so. external system. 

.The LAN 107 also includes information services components 108. Information 
15 services 108 includes a central database lOLand a front end controller 109 which acts as 
a general controller for the network 100. The controller 109 may continuously poll the 

^various CyTsJOd-requestinguiBformation -pertaining to ganung-transactions in the 

network 100. The CVTs 106 arei in tum, continuously polling the varioxis machines 
1 02. For example, if a credit device has been inserted in a gaming machine 1 02, that 
20 macliine will communicate an insertion event to its CVT 1 06 in response to the next 

CVT 1 06 poll. Then when the front end controller 1 09 polls the CVT 1 06, the CVT 1 06 
communicates the insertion event to the front end controller 1 09. 

The LAN 107 includes numerous work stations. A cashier's station 1 12 is 
included for redemption of credit devices created within the network 1 00. The cashier's 
25 station 112 includes a computer 114 with a printer 1 1 8 and a bar-code scanner 1 1 6 for 
reading credit devices. The network 100 may accommodate as many cashier stations 1 12 
as reqiiired to support a facility. 

Additional stations may be included in the LAN 107. For example, the LAN 1 07 
and may include a station in charge of security and a workstation in charge of 
30 surveillance. A soft count station 120 may also be included for daily verification of bills 
and tickets accepted gaming machines 102 in the network lOO; An audit station 122 may 

6 
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also be included for accounting purposes. Any of the statioiis in the LAN 107 may 
provide the current status of a credit device. Each of the stations on the LAN 107, 
including jthe front end controller 109, may be implemented on any of a variety of 
commercially available computer systems. Such machines include, but are not limited 
5 to, PC compatibles, DEC VAXs^ and UNIX machines. In alternative embodiments, the 
various network fimctions siich as froiit end control are accomplished by distributed 
processing. In such cases, the network fimctibns are\performed on multiple nodes. 

hi the depicted example, information services 108 also includes a file server 124 
,.: which is the main processor in the network. Its functions will be described in more 
1 0 detail below. A suitable file server machine is the Compaq 550 available from Compaq 
Computers. The file server communicates with all stations included on the LAN 107 in 
addition to an external host network .tiirough a modem. 

As is known to those of skill in the art, EFT hosts are typically mainfi-ame 
computers which route electronic funds transfer requests and authorizations between 

15 various sales or services establishments (a casino in this instance), and remote funds 

repositories such banks or credit unions. Compaq Computers provides many of the file 
sei-ver computers now used for this purpose. And ACI Company of Omaha, NE provides 
much of the banking software or "switch processing" software used by most of the major 
networks around the world. The EFT system may also include workstations, printers, 

20 multiplexers, modems, etc. connected as a network and communicating with the casiao 
to the . individual card issuing institutions over phone lines. 

EFT hosting may be provided by various widely used EFT service providers such 
:; as Cimis™ and hiterlinkTw. Such EFT service providers contract with various card 
issuing institutions (e.g., banks or other financial institutions) to provide EFT services. 
25 • In some instances they also contract with one or more very large EFT sei-vice providers 
.r such as Maestro^M and Interlinlc^M which together provide EFT services for most of the 
available funds repositories. Such services are further described in commonly owned 
United States Patent Application entitled "Cashless Transaction ClearingHouse" filed 
. August 25, 2000, which is incorporated by reference herein for all purposes. 

3 0 In some embodiments, the EFT host will be provided and maintained by a casino 

or gaming machine vendor. All EFT requests from gaming machines of the vendor or 
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casino would, in such cases, be routed tbxough the private EFT host. In addition, the 
host could process ATMj check authorization, and point of sale transactions within the 
casino. Ih such embodiments, fhe casino or gaming machine vendor providing hosting 
preferably contracts with the large service providers (e.g.. Maestro™ and Interlink™), 
5 rather than contracting with the smaller providers or the individual funds repositories. 

When a user wishes to play a gaming machine 1 02, he or she inserts credit 
through a credit acceptor included in the machine. The credit may include cash, coins, 
•game tokens or credit devices such as tickets and magnetic cards. The credit acceptor 
may be a coin acceptor, bill validator or a similar device which reads tickets or other 

1 0 suitable credit devices. The. cash, game tokens or tickets may be stored in the interior of 
the gaming machine in devices including ticket stackers, drop boxes, and token 
dispensers. At the start of interaction with tiie gaming machine, the player may enter 
player tracking information using a card reader, a keypad, and a flores'cent display. 
During the interaction, the player views game information using a video display. 

1 5 Usually, diiring the course of a game, a player is required to make a number of decisions 
that affect the outcome of the game. The player makes these choices using a set of 
player-input switches. 

After the player has completed interaction with the gaming machine, the player 
may receive a portable credit device from the machine which includes any credit 

20 resultittg from interaction with the gaming machine. By way of example, the portable 
credit device may be a ticket having a dollar valuie produced by a printer within the 
gaming macliine. A record of the credit value of the device will be stored in a memory 
device provided on the network 100 (e.g., a memory device associated with CVT 106 
and/or database 101). Any credit on the device may be used for further games on other 

25 gaming machines 102. Alternatively, the player may redeem the device at a designated 
change booth or pay machine. 

Having briefly discussed an exemplary gaming system suitable for use with of the 
present invention, the transaction information protection aspects of the invention, as well 
as other features and advantages of the present invention, may be better imderstood with 
30 reference to the figures and discussions that follow. As .mentioned earlier, the present 
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inveihtion implements a transaction signaiure to provide transaction information 
protection. 

In a preferred embodiment of the present invention, a portable credit device is 
earned by the player. The credit device may be a magnetic card, cash voucher, ticket, or 
5 any other form of portable credit device. Fig. 2A illustrates a ticket 200 in accordance 
V: : . with a specific embodiment of the present invention. 

The ticket 200 displays one or more transaction information elfements. The 
transaction information elements may include, for example, a casiao. identification 202, a 
ticket identification 204, a validation number 206, a date 208, a time 210, a ticket 

10 number 212, a value 214, and a machine identification number 216. The validation 

number 206 is a miique number generated vsrithin the network 1 GO such that each ticket 
200 and transaction may be uniquely identified, hi one embodiment, the time 210 refers 
to the time when the ticket 200 is printed. Other transaction information elements not 
shown which may be stored on the tickets 200 include a cluster controller address, ticket 

15 status, status change time and other related information. The ticket 200 may also display 
other information to assist the player such as instructions 217. The ticket 200 is typically 
produced each time a player completes a transaction on a gaming machine. 

The ticket 200 also includes a bar-code 218. The bar-code 218 stores one or 
more of the transaction information elements and transaction data in a manner which is 
20 readable by gaming machines 102 in the network 100. The bar-code 218 may include 
any of the transaction information elements listed above. For example, the bar-code 218 
may include the validation number 208 for unique identification of the ticket 200 by a 
gaming machine. 

By way of example, the ticket 200 may be a ticket used in the EZPay ticket 
25 system. The EZPay ticket system is fiiUy described in commonly owned U.S. Patent 
Application No. 09/544,884 entitled "Wireless Gaming Enyiroiiment", which is 
incorporated herein by reference. Although the present invention is primarily discussed 
with respect to the ticket 200, which the user carries, any suitable portable or transferable 
credit device capable is suitable for iise with the present invention. 
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As mentioned earlier, the present invention generates a transaction signature to 
protect transaction information from tampering. The transaction signature is computed 
using one or more of the transaction information elements (e.g., a combination of casino 
ID, time, and value). Generating the transaction signature may be performed at various 
5 tinies and from various sources. In a preferred embodiment, a transaction signature is 
generated by a main processor in conjimction with the network central database each 
time the user completes a transaction with a gaming machine. In this case, the 
transaction signature is generated from transaction information elements included in the 
most recent transaction. : The transaction signature may also be generated from other 
10 informatioii such as the status of the credit device, the time the ticket was generated, the 
amount on the ticket, etc. After generation of the fransaction signature, the transaction 
information and transaction signature are.-stored (preferably in the central database) for 
subsequent access and verification. 

Generally speaking, a transaction refers to interaction of a player with a gaming 
1 5 machine. Typically, the transaction begins when the player inserts credit into the 

machine. The transaction includes the player participating in one or more games on the 
machine. Usually, during the course of a game, the player is required to make a niimber 
of decisions that affect the outcome of the game. After the player has completed 
interaction with the gaming machine, the transaction is finished arid the player may 
20 receive a credit device from the machine which includes any credit resulting from 
interaction with the gaming machine. 

The transaction information used for generating the signature may vary. Broadly 
speaking, the transaction information used in generating the transaction signature may 
include any . data or information related to a transaction betcveen a player and a gaming 

25 machine. The transaction information used for generating the transaction signature need 
not be characteristic or unique by itself, but may be processed to provide a characteristic 
transaction signature. A characteristic transaction sighattire refers to a transaction 
signature which is substantially unique within a database. In some embodiments^ the 
transaction information used for generating the signature may include the user's 

30 identification (e.g., name or number), transaction termination time, a machine identifier, 
casino identification, final transaction value, ticket validation number, ticket printer time, 
machine identifier, cluster controller address, ticket status, or some combination thereof. 

10 
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Any technique for generating the transaction signature from the ch^ 
transaction information (the seed value(s)) may be employed. Preferably, it is a 
technique that cannot be readily discerned from the other information stored with the 
signature (e.g., other information in a database record). In some embodiments, a specific 
5 .algorithm is used to translate the transaction information into the transaction signature.. 
. The resulting transaction sigjiature produced by the algorithm may take the. form of a 
string of characters. The string of characters may include computer-generated symbols.. 
. such as numbers, letters, symbols, etc. For simplicity, the transaction signature is 
preferably provided "in the clear"; i.e.; without enayption of the string of characters. In 
1 0 another embodiment, the string of characters may be encrypted to improve protectionsr 
As one skilled in the art would appreciate, there exists an abundant number of ways ton 
create an encrypted key from the transaction information and the present invention may 
include any such encryption algorithm or mechanism. 

Jh other embodiments, the algorithm used to produce the transaction signature 
1 5 may vary over time to improve transaction information protection. By way of example, 
the algorithm may change every week. In one embodiment, the information used in 
generating the signature the may change. For example, in one week, the transaction 
information used for generating the signature of a ticket may include the user's name, the 
ticket print time and a machine identifier. The next week, the transaction information 
20 used for generating the signature may include the user's name, the gaming machine 

identifier and the final transaction value on the gaming machine. In addition, the order 
of transaction information elements used to generate the transaction sijgnature may also 
change to vaiy the algorithm and transaction signature. 

One exemplary algorithm for creating transaction signatures suitable for use with 
25 the present invention is a cyclic redundancy check (CRC) algorithm. To vary this CRC 
algorithm over time, the order of transaction information elements provided to the 
algorithm may vary as well as altering the initial seed value to the algorithm. Specific 
algorithms suitable for use with the present invention include the CRC- 16 algorithm and 
the CRC-32 algorithm. As one skilled in the art would appreciate, there exists aii 
30 abundant number of algorithms to create an encrypted key from the transaction 
information and the present invention may include any such algorithm. 
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As mentioned, the transaction information and transaction signature are recorded 
electronically in a inemory device within the network 100. FIG. 2B illustrates an - 
exemplary data structure 250 containing the- transaction data and a transaction signature 
in accordance with a specific embodiment of the present invention. The data stmcture 
250 includes a header portion 252 used- for transmission within the network. 100. A 
transaction information portion 254 contains some Or all of the transaction information. 
This may include the transaction time, validation number, ticket amount, etc* A 
transaction signature portion. 256 contarns'the transaction signature corresponding to the 
transaction information contained in the transaction information portion 254. In one 
embodiment, the data stmcture 250 is included in a network packet sent over a network 
from a central database to a gaming machine. This may occur, for example, when the 
gaming machine requests validation of a ticket from the central database. 

FIG. 3 illustrates a process flow 300 to record a transaction signature after a 
player completes one or more games on a playing machine in accordance with one 
embodiment of the present invention. Processes in accordance with the present . 
invention may include up to several a:dditiona] steps not described or illustrated here in 
order not to obscure the present invention. 

The process flow 300 begins with a request to finish interaction with a gaming 
machine (302). At this point, a processor within the machine may calculate one or more 
transaction elements associated with the transaction, e.g., the time and cash out value. 
The cash out value aJfter mteraction with the gaming machine may include winnings from 
the gaming machine. The transaction elements are .then sent to a central processor for 
the network which is coupled to a central database. The central processor then identifies 
one or more transaction information elements associated with the cash out transaction 
(304). These elements are then used to calculate a transaction signature for the 
transaction (306). ^ 

The transaction information and transaction signature may then be stored (308). 
In one embodiment, the transaction information and transaction signature are recorded in 
the central database of the gaming network. In addition, the transaction information and 
transaction signature may also be recorded in additional memory locations such as those 
fo\md in a cluster controller or CVT, for example. The transaction information and 
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transaction signature may be stored in various ways. In one embodinaent, the transaction 
information and transaction signature are stdred together as a liew record in a database 
after each transaction. In another embodiment where transaction information is updated 
in a progressive record, each time transaction infomiation is updated in the database, an 

5. updated transaction signature is automatically attached to the transaction infomiation. In 
this manner, the most recent transaction signature is verified whenever the transaction 

v.. information is accessed. ■ 

Upon subsequent access to the transaction infomiation, either for redemption by a 
gaming machine or at cash-out, the transaction signature is verified. Verifying the ■ 

1 0 transaction signatxure includes verification between the transaction signature stored in the 
database and a transaction signature calculated based on the transaction information at 
flie time of access. The transsiction information used at the time of access may include 
transaction information obtained fipom a credit device used with a gaming machine. Any 
discrepancies between the current calculated transaction signature the transaction 

1 5 signature stored in the database may be investigated. In this manner, any alteration to the 
transaction information in the database may be. detected. In some embodiments, the 
transaction infomiation may additionally be verified upon subsequent access to the 
transaction information. Verifying the transaction information may include verification 
between the transaction information stored in the database and the transaction 

20 information at the time of access by a credit device in a gaining machine, for example. 

In one. embodiment^ a transaction signature is verified each time transaction 
■» information related to the transaction signature is updated and each tiine the transaction 
information is accessed, e.g., for redemption at a cashier's station. Note that this need 
not be associated with a credit transaction such as redemption. It may also occur at 

25 random times, when triggered by a database integrity check, for example. In one 

embodiment, when credit devices are to be redeemed, only credit devices with valid ^ 
transaction signatures are allowed redemption. In another embodiment, when transaction 
information is retiieved from the database to be sent to a CVT, a cashier's station or a 
gaming machine, only transaction infonnation having a valid transaction signature is 

30 sent. In either case, a system audit log may be created and maintained that contains the 
results of requests for transaction information and includes requests which contain 
requests for tiansaction information having invaUd transaction signatures. 

13 
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FIG. 4 illustrates a process flow 400 for validating a transaction signature- in ' 
accordance with a specific embodiment of the present invention:, Processes in 
accordance with the present invention may include up to several additional steps not 
described or illustrated here in order not to obscure the present invention. 

5 As mentioned before, according to one embodiment, a player may carry a credit 

. device for use with gaming machines of a gaming machine network. The player may 
redeem the credit device and any value on the credit device at any gaming machine, a 
designated cash but window or a pay machine. When a credit device is redeemed at a 
cash out window, the cashier may verify the device by inputting the device number into 

10 - the cashier station computer. In one embodiment where the credit device is a ticket 

including a bar-code, the cashiier may input the ticket identification by scanning the ticket 
with a bar-code scanner. The most recent ticket transaction information and h'ansactidn 
signature will be stored in a central -database of the system. Thus, upon receiving a 
request to validate a cash out transaction (402), the system will retrieve a record of the 

1 5 transaction (404); The record of the transaction will include a transaction signature and 
any transaction information stored in the central database. 

The process flow 400 then calculates the transaction .signature fi-om the relevant 

transaction information elements in the database record (406). The process flow 400 
compares the calculated transaction signature with the transaction signature recorded in 
20 the database (408). hi addition, the process flow 400 may also compare one or more of 
the transaction informatioh elements for consistency between the database and the credit 
device. 

If the calculated transaction signature (from 406) matches the transaction 
signature recorded in the database (410), vahdation of the cash out transaction is allowed 

25 (412). If the vahdation request occurs at a gaming machine, the player will be credited ^ 
the corresponding amount on the gaming machine. If the validation request occurs at a 
cashier's station, the player will be paid with the corresponding amount according to the 
cash out value stored in the database. The system may also print out a verification 
receipt for each ticket at the cashier's station. The cashier may store the ticket and the 

30 verification receipt. If the calculated transaction signature (firom 406) does not match the 

14 
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triansaction signature recorded in the database (410), the cash out transaction is. prevented 
(414), the discrepancy may be logged and investigated (416): 

In one embodiment, the transaction signature and/or transaction information in 
the database are verified each time the validation number is accessed, each time the 
5 transaction information is updated, and each time credit associated with the validation 
number is to be redeemed. In some embodiments, the transaction information may be 
•verified using a comparison between the stored transaction signature and a newly 
calculated transaction signature based on transaction infonnation not in the database, hi . 

TTT^s^Ms-ease^the-new transaeti0n^i^ature-is-generated^usiBg-faansaGtion4nfor^ 

10 - an alternate source outiside the database at the time of access. By way of example, the 
, . .^..alternate source may be the credit device used by the player. Again, xf the two 

transaction signatures are different, the transaction infonnation may have been altered 
and the discrepancy is logged and investigated. 

In one embodiment, the network 100 may perform periodic validation of the 
15 transaction information in the database, In a specific embodiment, the network 100 
performs periodic validation by comparing transaction signatures locally stored in the 
CVTs 106 with transaction signatures stored in the database. Any discrepancies between 
transaction signature stored in CVT's 106 and those in database may elicit fiirther 
investigation. 

20 The transaction informatioh and transaction signature are stored within a 

database. The database may be centralized to the entire system or a database may 
included local to a CVT for a certain number of gaming machines. Any conventional 
, iidatabase tool is suitable for use with the present invention. By way of example, a DBA 
or SQL database are both suitable for use with the present invention. 

25 PIG. 5 presents a logical representation of a database 500 for storing transaction 

infonnation with a transaction signature in accordance with a specific embodiment of 
this invention. The database 500 includes a number of records 501 each relating to an 
individual transaction. A primary key 502 uniquely identifies each record 501 . In one 
embodiment, tlie primary key 502 is the validation number 206 produced by a gaming 

30 machine at cash out of the credit device. Each record 501 may also include a number of 
transaction information elements such as a print time 504, a machine ID 506, a cashier 

15 
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value validation and a redemption status 510. A trausactioh signature 512 is also . 
included in each record 501. The database 500 may also include numerous other 
transaction information elements such as the machine number, the cluster controller 
number, or any other eleinents stored on the ticket 200. 

In one embodiment, the transaction signature is generated and appended to. the 
transaction information in the database whenever the transaction information is updated, 
hi this manner, a transaction signature is attached to the transaction information in the ■ 
database based on the most recent transaction information. ••' ' 

Advantageously, tiie present invention prevents unauthorized tampering of 
transaction information stored in a database of a gaming network. Correspondingly, the 
transaction information stored in the database may be kiept "in the clear". In other words, 
the transaction information may be kept in the database without encrj'ptioh which may 
•encumber transmission and thereby decrease performance of the- network. The above- 
mentioned recording and verification of transaction signatures also prevents anyone with 
a standard database tool to create new tickets in the system database and attempt to 
redeem such tickets at a cashier terminal, a cluster controller or machine in the network. 

Although the foregoing invention has been described in some detail for purposes 
of clarity of understanding, it will be apparent that certain changes and modifications 
may be practiced within the scope of the appended claims. For instance, while the 
methods and systems of this invention have been described primarily in reference to 
protecting the cash out value of the transaction information, the invention is not limited 
to protecting just this element of the transaction information. Indeed, the transaction 
information protected by the present invention may include any of the transaction 
information elements stored in the database such as the ticket identification, the time, the 
validation number, etc. Therefore, the present examples are to be considered as 
illustrative and not restrictive, and the invention is not to be limited to the details given 
herein, but may be modified within the scope of the appended claims. 
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1 . A method of protecting transaction information stored in a database associated 
with gaming machines, said mefliod comprising: 

5 identifying a transaction resulting from player interaction with a gaming machine; 

generating a first transaction sigpature from one or more tr£ul§action info 

elements included in the transaction; 

recording the transaction information elements and the first transaction signature 
in the database; and 
10 verifying the first transaction signature. 

2. Hie method of claim 1 wherein the player interaction with the gaming machine 
includes changing an amount of credit on a credit device used by the player to play the 
gaming machine. 

15 

3. The method of claim 2 wherein the first transaction signature is verified prior to a 
subsequent transaction. 

4. The method of claim 1 wherein verifying the first transaction signature 
20 comprises: 

generating a second transaction signature fix)m transaction information in ttie 
database; and 

comparing the first transaction signature with the second transaction signature, 

25 5. The method of claim 4 further comprising providing redemption of any credit on 
the credit device based on the verification. 

6. Themetliodof claims wherein verifying occurs at a cashier station. 
30 7 . The method of claim 1 further comprising verifjing the transaction information. 
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8. The method of claim 1 wherein the one or more transaction information elements 
indude at least one of a ticket identification number, a ticket amount, a ticket print time, 
a machine identification, and a ticket status. 

9. Tiie method of claim 1 wherein, generating the first transaction signature 
comprises calculating the first transaction signature firom the one or more transaction- 
information elements using a first algorithm. 

10. The method of claim 9 ftuther comprising generating a second transaction ' 
signature from the one or more transaction information elements iising a second 
algorithm, the second algorithm being different from the first algorithm and being used 
at a different time than the first algorithm. 

1 1 . The method of claim I wherein the first transaction signature is characteristic. 

1 2 . The method of claim 1 wherein verifying the first transaction signature is 
performed by a central processor. 

13. The method of claim 1 fiuther comprising cashing but credit associated with the 
transaction afi:er verifying the transaction signature. 

14. A method of using a credit device on a gaming machine in a gaming machine 
network, the method comprising: 

initiating interaction between the gaming machine and a player; 
tenninating interaction with the player; 

recording a set of transaction information elements related to the interaction; / 
generiatihg a transaction signature from one or more of the set of transaction 
information elements; 

recording the transaction signature with the set of transaction information 

elements; and 

providing the credit device to the player. 
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1 5. The method of claim 14 wherein initiating the interaction uses one of a coin, a 
game token, or the credit device. 

1 6. The method of claim 14 wherein the set of transaction information elements 
5 include at least ohe of a date, a transaction number and a credit device value. 

. * ■ ■ • . ^ 

1 7. The methpd^:6f claim 14 wherein the transaction information and the transaction 
sigiVaUire are stored within a database of the gaming machine network. 

10 18. . The methodiof claim 14 wherein the credit device is a ticket. ' 

1 9. The method of claim 14 further including initiating interaction with a second 
gaming machine in the gaming machine network using the credit device. 

1 5 . 20. The method of claim 19 the further including verifying the transaction signature 
before initiating interaction with the second gaming machine. 

21. A database for use in a gaming machine network, the database comprising a set 
of records, each record comprising a first portion including a primary key which 

20 uniquely identifies the record within the set of records, a second portion including one or 
more transaction information eleiiieiits, and a third portion including a transaction 
signature. 

22. The database of claim 21 wherein the transaction information elements include at 
25 least one of a ticket^adentification number, a ticket amount, a ticket print time, a machine v -. 

identification and a ticket status. 

23.. The database of claim 21 wherein the transaction signature is produced from one •, 
or more of the ti-ansaction information elements using an algorithm. . 

30 

24. The database of claim 2 1 wherein one of the one or more transaction information 
elements may not be updated unless the transaction signature is verified. 

19 
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25 . A cashless instrument transaction network for validating the use of cashless 
instruments across separate gaiiring properties, each of which generates and validates 
cashless instruments,- the cashless instrument transaction network comprising: 

a network-.ihter&ce allowing the cashless instrument transaction network to 
communicate with each of the separate gaining properties; and 

: a processor configured or desigiied to (i) receivexashless iiistrument validation 
requests via the network interface &om a first property for a cashless instrument- 
presented at the first prbpieity (ii) verify a transaction signature generated firom one or 
more transaction information elements-included when the instrument was generated 
previously with one or more transaction information elements included in the cashless 
instrument presented at. the first property. 

26. The cashless instrument transaction network of claim. 25, wherein the transaction 
signature was generated previously fi^om a second property. 

■ 27 The . cashless instrument-transaction network o£claim .25^ wherein .the first . 

property is.one of a gaming machine and a cashier's station. 

28. The cashless instrument transaction network of claim 25, further comprising a 
transaction database containing cashless instrument transaction information. 

29. The cashless -instrument transaction network of claim 28, wherein the database 
further comprises transaction signatures associated with the cashless instrument 
transaction information. 

30. The cashless instrument transaction network of claim 25, wherein the cashless 
instrument is selected fi-om the group consisting of a smart cart card, a debit card, a bar- 
coded ticket and an EZ pay ticket voucher. 
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